SmartNIC Security Isolation in the Cloud with S-NIC
Yang Zhou, Mark Wilkening, James Mickens, Minlan Yu
摘要
Modern smart NICs provide little isolation between the network functions belonging to different tenants. These NICs also do not protect network functions from the datacenter-provided management OS which runs on the smart NIC. We describe concrete attacks which allow a network function's state to leak to (or be modified by) another network function or the management OS. We then introduce S-NIC, a new hardware design for smart NICs that provides strong isolation guarantees. S-NIC pervasively virtualizes hardware accelerators, enforces single-owner semantics for each line in on-NIC cache and RAM, and provides dedicated bus bandwidth for each network function. Using this design, we eliminate side channels involving shared hardware state, and give each network function the illusion of having a private smart NIC. We show how these virtual NICs can be integrated with preexisting datacenter technologies for virtual LANs and trusted host-level computations like SGX enclaves. The overall result is that S-NIC enables strongly-isolated, NIC-accelerated datacenter applications; in these applications, network functions and host-level code receive hardware-guaranteed isolation from other applications and the datacenter provider.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Toleo: Scaling Freshness to Tera-scale Memory Using CXL and PIMJuechu Dong, Jonah Rosenblum, Satish NarayanasamyASPLOS 2024 · 被引用 8 次
- Nezha: SmartNIC-based Virtual Switch Load SharingXing Li, Enge Song, Bowen Yang, Tian Pan 等SIGCOMM 2025 · 被引用 3 次
它引用的顶会 Paper12
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- ARMageddon: Cache Attacks on Mobile DevicesMoritz Lipp, Daniel Gruss, Raphael Spreitzer, Clémentine Maurice 等USENIX Security 2016 · 被引用 451 次
- T-SGX: Eradicating Controlled-Channel Attacks Against Enclave ProgramsMing-Wei Shih, Sangho Lee, Taesoo Kim, Marcus PeinadoNDSS 2017 · 被引用 431 次
- Translation Leak-aside Buffer: Defeating Cache Side-channel Protections with TLB AttacksBen Gras, Kaveh Razavi, Herbert Bos, Cristiano GiuffridaUSENIX Security 2018 · 被引用 357 次
相关 Paper
- SmartNIC Performance Isolation with FairNICStewart Grant, Anil Yelam, Maxwell Bland, Alex C. SnoerenSIGCOMM 2020 · 被引用 62 次
- Composable Cachelets: Protecting Enclaves from Cache Side-Channel AttacksDaniel Townley, Kerem Arikan, Yu David Liu, Dmitry Ponomarev 等USENIX Security 2022
- OSMOSIS: Enabling Multi-Tenancy in Datacenter SmartNICsMikhail Khalilov, Marcin Chrapek, Siyuan Shen, Alessandro Vezzu 等USENIX ATC 2024 · 被引用 14 次
- TNIC: A Trusted NIC Architecture: A hardware-network substrate for building high-performance trustworthy distributed systemsDimitra Giantsidi, Julian Pritzi, Felix Gust, Antonios Katsarakis 等ASPLOS 2025 · 被引用 4 次
- AEX-Notify: Thwarting Precise Single-Stepping Attacks through Interrupt Awareness for Intel SGX EnclavesScott Constable, Jo Van Bulck, Xiang Cheng, Yuan Xiao 等USENIX Security 2023
